Flash Loan Attacks Caused $1.211 Billion in DeFi Losses, Study Finds
Preface
Flash loans are a distinctive feature of decentralized finance (DeFi): they allow users to borrow assets without collateral, as long as the loan is repaid within the same blockchain transaction. This design can support legitimate trading and other financial activity, but it can also give attackers rapid access to substantial funds for exploiting vulnerabilities. Research published in the Journal of Financial Crime examines how this risk played out between February 2020 and July 2024. The study identified 72 flash loan attacks among 254 successful DeFi attacks and estimated that flash loan incidents accounted for $1.211 billion in losses. It also charts a shift in attack patterns: although price manipulation remained important, exploits targeting protocol logic became a larger share of losses over time. The findings offer a detailed view of the scale, methods and human consequences of flash loan attacks.
Lazy bag
Between February 2020 and July 2024, 72 flash loan attacks caused $1.211 billion in losses, or 18.44% of the $6.568 billion lost across all successful DeFi attacks covered by the study. More than 80% of flash loan losses occurred on Ethereum. Researchers documented 14 attack types, broadly involving price-feed manipulation or weaknesses in protocol logic. Logic exploits were less frequent but increasingly costly, accounting for 55% of flash loan losses from February 2022 to July 2024. The authors describe these incidents as significant and unpredictable risks, but not existential threats to DeFi.
Main Body
A study published in the Journal of Financial Crime estimates that flash loan attacks drained $1.211 billion from decentralized finance platforms between February 2020 and July 2024. The research was conducted by Professor Tim Hall of the University of Winchester and Remo Stieger, a former partner at Swiss risk intelligence firm SyntiFi. The researchers identified 72 flash loan attacks among 254 successful attacks on DeFi during the period. Those 254 incidents caused $6.568 billion in losses, making flash loan attacks responsible for 18.44% of the total.
Flash loans allow users to borrow assets from a liquidity pool without providing collateral. The defining condition is that the borrowed amount must be repaid within the same blockchain transaction. If repayment does not happen, the transaction is generally reversed. This structure makes large sums available very quickly, which can be useful in legitimate financial operations. It can also enable an attacker to assemble the capital required to manipulate a market, exploit a software weakness or carry out a complex sequence of actions before the transaction concludes.
The study found that more than 80% of flash loan attack losses occurred on Ethereum. Individual incidents ranged in value from $80,000 to $197 million. Attacks that stole $10 million or more accounted for over 88% of the total losses. These figures illustrate how a relatively limited number of especially large incidents can dominate the aggregate financial impact, even when many separate attacks occur.
The researchers classified 14 types of flash loan attack into two broad categories. One category involves manipulating price feeds, often called oracles, that provide protocols with information about asset prices. If an attacker can distort the price used by a platform, the protocol may make decisions based on inaccurate data. A manipulated price can, for example, affect borrowing limits, collateral values or the exchange rates used in a transaction. Flash loans can provide the temporary liquidity needed to influence these conditions, although the precise mechanism varies by exploit.
The second category involves exploiting flaws in a protocol’s underlying logic: the rules and code that govern how a platform handles deposits, withdrawals, trades, collateral and other operations. Such vulnerabilities may allow actions that developers did not intend, even if the protocol’s price data is not manipulated. The study found that logic exploits were less common than other attack types but produced higher average losses. This distinction matters because it suggests that security risks are not limited to faulty price inputs; the design and implementation of a protocol’s core functions can also create high-impact weaknesses.
The share of losses linked to logic exploits increased over the period examined. These exploits accounted for 28% of flash loan attack losses between February 2020 and January 2022. From February 2022 to July 2024, their share rose to 55%. The researchers’ interpretation is that as platforms address known weaknesses, attackers may shift toward other vulnerabilities, including flaws in protocol logic. The figures describe a change in the composition of losses; they do not mean that every platform experienced the same trend or that one category entirely replaced another.
Four attack types together accounted for more than 81% of the reported losses: price oracle attacks, donate function logic exploits, reentrancy attacks and one governance attack. The governance attack alone cost $181 million. These categories reflect different ways of taking advantage of DeFi systems. Oracle attacks target price information; donate function exploits abuse how a protocol accounts for contributed assets; reentrancy attacks exploit the order in which contracts process interactions; and governance attacks target mechanisms through which decisions about a protocol can be made. The study’s classification highlights the range of technical weaknesses that can be involved in apparently similar incidents.
Attack activity did not remain constant. The authors describe phases of growth and consolidation, a pattern they say may indicate that platforms improved security after attacks while attackers searched for new vulnerabilities. The research does not treat this cycle as proof that defenses permanently eliminate risk. Rather, it suggests that security measures and adversarial techniques develop alongside one another. A vulnerability can be patched on one platform while a different weakness, or a similar weakness in another system, remains available.
To add operational context, the study included an interview with a platform that suffered a major flash loan attack. The platform was granted anonymity at its request. Its representative said the exploited bug had passed “ourselves and several of the auditors” and had gone unnoticed on-chain for more than a year. The account underscores the limits of relying on any single review process. Audits and monitoring can reduce risk, but the interview illustrates that a vulnerability may evade multiple checks and remain unrecognized until it is exploited.
Hall also described the attacker’s behavior after the incident. The attacker began “taunting” the platform on social media, which, he said, “led to some victims engaging with the attacker and outlining the devastating impacts that the loss of this money had on them.” The episode points to consequences beyond the immediate technical and financial loss: victims may be drawn into public exchanges with attackers, and the incident can affect people who depended on the platform or its services.
The platform representative distinguished between “hobbyist individual researchers” and professional state-level or organized crime groups, citing North Korea. In the representative’s assessment, attacks by professionals “are not at all advanced” from a blockchain security perspective. That observation does not diminish the scale of harm. A technically straightforward attack can still cause severe losses if it targets a valuable vulnerability or a system holding substantial assets. The representative also described the effect on teams, saying attacks “most often it ends up fracturing them and destroying them,” even when funds are recovered.
The researchers found that losses exceeded 0.5% of the value borrowed through flash loans in only one six-month period, while flash loan use continued to grow. The comparison offers context: the overall volume of flash loan activity and the losses associated with attacks are not identical measures. A low loss share across most periods does not remove the possibility of severe individual incidents, as the reported range and the largest attacks demonstrate.
The authors characterize flash loan attacks as significant, increasingly sophisticated and unpredictable, but “not existential” threats to DeFi. This assessment balances substantial losses against the broader continuation of decentralized finance activity. It also emphasizes the importance of studying how attacks work, how protocols respond and how losses affect users and teams. Hall said the research should not be viewed only as academic work, noting that its analysis has applications for the cryptocurrency industry, regulators, and legal and law enforcement agencies.
The study period ended in July 2024, but a later incident illustrates the continuing relevance of the subject. Decentralized exchange Bunni shut down in October 2025 following an $8.4 million exploit that used flash loans. The exchange said it could not afford the cost of a secure relaunch. This later case is separate from the study’s dataset, but it demonstrates that the consequences of an exploit can extend beyond the stolen funds: a platform may also face the expense of rebuilding, improving security and restoring user confidence.
Overall, the research presents flash loan attacks as a changing security challenge rather than a single, uniform method of theft. Price manipulation, protocol logic errors and other exploit types can produce very different outcomes, while the availability of temporary liquidity may help attackers execute them. The study’s central implication is that continuous security work matters: protocols must consider both external data and the logic of their own systems, while industry participants and public authorities can use incident analysis to better understand recurring risks and their consequences.
Key Insights Table
| Aspect | Description |
|---|---|
| Study period and incidents | Researchers identified 72 flash loan attacks between February 2020 and July 2024 among 254 successful DeFi attacks. |
| Reported losses | Flash loan attacks caused $1.211 billion in losses, equal to 18.44% of the $6.568 billion lost across all attacks covered. |
| Ethereum concentration | More than 80% of flash loan attack losses occurred on Ethereum. |
| Attack size | Individual attacks ranged from $80,000 to $197 million; attacks of $10 million or more accounted for over 88% of losses. |
| Changing exploit patterns | Logic exploits rose from 28% of losses between February 2020 and January 2022 to 55% from February 2022 to July 2024. |
| Major attack types | Price oracle attacks, donate function logic exploits, reentrancy attacks and one governance attack accounted for more than 81% of losses; the governance attack cost $181 million. |
| Later example | Bunni shut down in October 2025 after an $8.4 million flash loan exploit, citing the cost of a secure relaunch. |
Last edited at:2026/10/6
